CVE-2010-0705

high

Description

Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.

References

http://www.vupen.com/english/advisories/2010/0449

http://www.trapkit.de/advisories/TKADV2010-003.txt

http://www.securitytracker.com/id?1023644

http://www.securityfocus.com/bid/38363

http://www.securityfocus.com/archive/1/509710/100/0/threaded

http://secunia.com/advisories/38689

http://secunia.com/advisories/38677

http://osvdb.org/62510

http://forum.avast.com/index.php?topic=55484.0

Details

Source: Mitre, NVD

Published: 2010-02-25

Updated: 2018-10-10

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High